Buffer overflow in the Overlay Transport Virtualization (OTV) GRE feature in Cisco NX-OS 5.0 through 7.3 on Nexus 7000 and 7700 devices allows remote attackers to execute arbitrary code via long parameters in a packet header, aka Bug ID CSCuy95701.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCisco Nx Os
OSCisco4.1.\(2\)4.1.\(3\)4.1.\(4\)4.1.\(5\)4.2.\(2a\)4.2\(3\)4.2\(4\)4.2\(6\)4.2\(8\)5.0\(2a\)5.0\(3\)5.0\(5\)5.1\(1\)5.1\(1a\)5.1\(3\)+ 31 more
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCEMemory
CWE
Related vulnerabilities
CVE-2021-1361CRITICAL9.8PL ✓same product
Cisco NX-OS: nieautoryzowany dostęp do plików przez port TCP 9075
CVE-2018-0310CRITICAL9.8PL ✓same product
Cisco FXOS/NX-OS: buffer overread w Cisco Fabric Services umożliwia DoS lub wyciek danych
CVE-2018-0301CRITICAL9.8PL ✓same product
Cisco NX-OS NX-API — buffer overflow umożliwiający RCE jako root
CVE-2016-1341CRITICAL9.8PL ✓same product
Puste hasło root w Cisco NX-OS na urządzeniach Nexus 2000 Fabric Extender
CVE-2024-20267HIGH8.6same product
A vulnerability with the handling of MPLS traffic for Cisco NX-OS Software could allow an unauthenticated, rem...